Skip to content

ISO 27001 internal audit

An internal audit examines whether the ISMS meets the selected requirements and works in practice. Plan the investigation, collect evidence and follow up findings.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Run the ISO 27001 readiness scan

Decide what the investigation should answer

An internal audit helps the organisation understand how its management system operates. Establish the objective, boundaries and assessment criteria before starting. An access management audit might examine whether requests, changes and removals follow the organisation’s agreed procedures. The auditor compares actual operation with those procedures and applicable requirements. An interview without criteria can easily produce opinions rather than testable findings.

Build an audit programme suited to the organisation

Distribute investigations across relevant processes and ISMS activities. Consider changes, risks and previous findings. A new service or recurring error may justify examining a topic earlier. Record who maintains the programme and how changes are handled. ISO/IEC 27001 contains ISMS requirements; ISO 19011:2026 provides guidance on auditing management systems.

Arrange a competent and impartial assessment

Select an auditor who understands the subject and can maintain sufficient distance from the work examined. Avoid having someone approve their own work without safeguards. In a small team, a colleague from another process or external support may help. Make potential interests visible and explain how the arrangements support an unbiased assessment.

  1. Agree the objective and schedule with the process owner.
  2. Read relevant procedures and previous results.
  3. Select samples and discuss actual situations.
  4. Compare explanations with available records.
  5. Clarify factual uncertainties before finalising the report.

Fictional example: changes to customer environments

A fictional software supplier requires review of production changes. The internal auditor selects changes from different periods, including an emergency change. That case lacks the agreed retrospective review. The report identifies the internal requirement, the record examined and the missing step. Its conclusion remains proportionate to the investigation: one exception does not automatically demonstrate that every change is handled incorrectly.

Turn findings into follow-up

Document findings clearly, including the relevant requirement and supporting facts. Give unresolved questions an explicit status. Assign follow-up and check whether the response adequately addresses the problem through corrective action. The audit checklist supports practical questions, while management review uses results for management decisions. Retain the original finding so that later reviewers can understand why the action was needed.

Primary sources for this topic

Frequently asked questions

Can an employee carry out the internal audit?
Yes, employees can perform internal audits when they have sufficient competence and can assess the subject objectively. Consider their involvement in the work and any competing interests. A different process owner or an external auditor may help a small team. Record how the chosen arrangements support both subject knowledge and an unbiased evaluation of the evidence.
Is an internal audit the same as a certification audit?
No. An internal audit serves the organisation’s own evaluation and improvement of its ISMS. A certification audit operates within a certification body’s assessment process. Both may use interviews and records, but they have different clients and purposes. A strong internal audit report is not a certificate and does not guarantee a positive external certification decision.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)